CVE-2026-105835High· 7.4▾ TwilightPLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-mi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full access token.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76940High· 7.5Ebyte NA111-M Improper Restriction of Excessive Authentication Attempts
CVE-2026-105638Critical· 9.1Plane is an open-source project management tool
CVE-2026-105237Low· 3.7A vulnerability was detected in linlinjava litemall up to 1.8.0
CVE-2026-97363High· 7.5The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
CVE-2026-102825Low· 3.7Russh is a Rust SSH client and server library
CVE-2026-102334High· 7.4Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account